Open
Cached
·
just now
76/100
SECURITY SCORE
Detected Technologies
Certificate Information
Subject
CN=dufdd.com
Issuer
C=US, O=Let's Encrypt, CN=R13
Valid From
February 04, 2026
Valid Until
May 05, 2026
78 days
Public Key
RSA
4096 bit
Strong
Signature Algorithm
SHA256-RSA
SHA-256 Fingerprint
03:27:88:4E:C8:22:51:3D:3E:44:6D:7E:53:6E:FC:8E:30:C2:1A:36:24:48:29:C7:2D:BB:E5:16:E8:94:03:0A
Alternative Names
Security Configuration
TLS Protocols
TLS 1.2
TLS 1.3
Forward Secrecy
Supported
(Modern clients use PFS)
HTTP Security Headers
Status
Strict-Transport-Security
Missing
Not configured
Content-Security-Policy
Missing
Not configured
X-Frame-Options
Missing
Not configured
X-Content-Type-Options
Missing
Not configured
Referrer-Policy
Missing
Not configured
Permissions-Policy
Missing
Not configured
Recommendations
- • Add Strict-Transport-Security header with max-age of at least 1 year
- • Add Content-Security-Policy header to prevent XSS attacks
- • Add X-Frame-Options: DENY or SAMEORIGIN to prevent clickjacking
- • Add X-Content-Type-Options: nosniff
- • Add Referrer-Policy header (recommended: strict-origin-when-cross-origin)
- • Consider adding Permissions-Policy to control browser features
CAA Records (Certificate Authority Authorization)
CAA Records
Not Configured
(Any CA can issue certificates)
CAA Issues
- • No CAA records configured - any CA can issue certificates
Recommendations
- • Implement CAA records to restrict which CAs can issue certificates for your domain
- • This adds an extra layer of security against unauthorized certificate issuance
- • Example: Add CAA record 'example.com. CAA 0 issue "letsencrypt.org"'
- • Consider adding 'iodef' record to receive security incident reports
Subject Alternative Names
89 domains
xtgpay.cc
*.xtgpay.cc
*.admin.xtgpay.cc
bird-college.co
*.bird-college.co
btn-wildlife.org
*.btn-wildlife.org
cncpts.online
*.cncpts.online
*.www.cncpts.online
dufdd.com
*.dufdd.com
*.ww16.dufdd.com
farhana.live
*.farhana.live
filminvazio.bet
*.filminvazio.bet
*.b.flake.bet
*.controle.flake.bet
flake.bet
*.flake.bet
*.gguehcontrole.flake.bet
gof.life
*.gof.life
helpteph.site
*.helpteph.site
*.mailx.helpteph.site
*.api.incantohomes.store
incantohomes.store
*.incantohomes.store
inkiri.org
*.inkiri.org
*.en.joohoney.shop
joohoney.shop
*.joohoney.shop
kosakowo.info
*.kosakowo.info
*.qanhnaikbc.kosakowo.info
*.random.kosakowo.info
*.www.kosakowo.info
laserart.studio
*.laserart.studio
lmx.au
*.lmx.au
*.mife.lmx.au
lojasasm.com
*.lojasasm.com
medcschoolguru.com
*.medcschoolguru.com
ofoghmandegar.com
*.ofoghmandegar.com
pay2.au
*.pay2.au
prefer.today
*.prefer.today
roselinetoday.com
*.roselinetoday.com
serkanhirdavatb2b.com
*.serkanhirdavatb2b.com
shohighmarkotc.com
*.shohighmarkotc.com
shopssixteen.com
*.shopssixteen.com
shridaddajichildcareayurveda.com
*.shridaddajichildcareayurveda.com
suezhao.com
*.suezhao.com
*.ww25.suezhao.com
tax-lawyers.xyz
*.tax-lawyers.xyz
tetapoke.com
*.tetapoke.com
*.dev.torrentino.website
*.kino.torrentino.website
*.ru.torrentino.website
*.rus.torrentino.website
*.skachat.torrentino.website
torrentino.website
*.torrentino.website
wowdels.me
*.wowdels.me
*.m.xinghuozk.com
*.random.xinghuozk.com
*.ww38.xinghuozk.com
*.www.xinghuozk.com
xinghuozk.com
*.xinghuozk.com
xvroovy.com
*.xvroovy.com
Other domains in certificate